CVE-2026-55689
openfga openfga, helm charts
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
- CVSS
- 8.1
- EPSS
- 0.30% 22.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10